{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T10:03:34Z","timestamp":1779962614851,"version":"3.53.1"},"reference-count":64,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T00:00:00Z","timestamp":1779926400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T00:00:00Z","timestamp":1779926400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100004739","name":"Youth Innovation Promotion Association of the Chinese Academy of Sciences","doi-asserted-by":"publisher","award":["No.2021156"],"award-info":[{"award-number":["No.2021156"]}],"id":[{"id":"10.13039\/501100004739","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Key Research and Development Program of China","award":["No.2023YFC2206402"],"award-info":[{"award-number":["No.2023YFC2206402"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>System call security is crucial for host-based intrusion detection, as security-sensitive system calls (e.g., execve, mprotect) play a vital role in completing attacks. However, existing defense methods face significant limitations. Static analysis and system call filtering cannot prevent the malicious use of necessary syscalls, while runtime methods based on control-flow, syscall sequences, or parameter integrity are vulnerable to sophisticated attacks, such as data-only attacks, that mimic benign execution patterns. In this paper, we propose a novel contrastive learning framework, SysAlign, for system call security that ensures the semantic consistency between a system call\u2019s macro-level and micro-level intents. SysAlign learns the macro-level intent by the sequence of system calls, which reflects the broader objective of a program phase. The micro-level intent is derived from the specific execution path, capturing the detailed execution context of system calls. Malicious system calls disrupt this consistency, leading to a detectable misalignment between the two intents. To minimize the overhead, we efficiently represent micro-level intent using critical points instead of tracking full execution paths. These points are extracted via dominator tree analysis on the program\u2019s over-approximated control-flow graph, effectively balancing rich semantics with performance. Additionally, to address the scarcity of attack data, our framework incorporates a tailored negative sampling strategy, enhancing the model\u2019s robustness. We evaluated SysAlign on real-world applications, including Nginx, NullHttpd, cURL, and SQLite3. The results demonstrate that our method effectively detects a diverse range of malicious system call behaviors, including those resulting from control-flow hijacking and data-only exploits. Our approach achieves an F1-score exceeding 96% with a performance overhead below 7%. This work presents a practical and effective advancement in system call security, significantly outperforming existing techniques.<\/jats:p>","DOI":"10.1186\/s42400-026-00595-2","type":"journal-article","created":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T09:19:27Z","timestamp":1779959967000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Sysalign: protect system calls via semantic alignment of critical paths and syscall sequences"],"prefix":"10.1186","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2827-0243","authenticated-orcid":false,"given":"Yinhao","family":"Qi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chen","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xinghu","family":"Han","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaobo","family":"Yang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tian","family":"Tian","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bo","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhigang","family":"Lu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,5,28]]},"reference":[{"key":"595_CR1","doi-asserted-by":"publisher","unstructured":"Abadi M, Budiu M, Erlingsson U, Ligatti J (2005) Control-flow integrity. In: Proceedings of the 12th ACM Conference on Computer and Communications Security. CCS \u201905, 340\u2013353. Association for Computing Machinery, ??? . https:\/\/doi.org\/10.1145\/1102120.1102165","DOI":"10.1145\/1102120.1102165"},{"key":"595_CR2","doi-asserted-by":"crossref","unstructured":"Agadakos I, Jin D, Williams-King D, Kemerlis VP, Portokalidis G (2019) Nibbler: debloating binary shared libraries. In: Proceedings of the 35th Annual Computer Security Applications Conference, 70\u201383","DOI":"10.1145\/3359789.3359823"},{"key":"595_CR3","doi-asserted-by":"crossref","unstructured":"Alves-Foss J, Song J (2019) Function boundary detection in stripped binaries. In: Proceedings of the 35th Annual Computer Security Applications Conference, 84\u201396","DOI":"10.1145\/3359789.3359825"},{"key":"595_CR4","doi-asserted-by":"crossref","unstructured":"Andriesse D, Slowinska A, Bos H (2017) Compiler-agnostic function detection in binaries. In: 2017 IEEE European Symposium on Security and Privacy (EuroS&P), 177\u2013189 . IEEE","DOI":"10.1109\/EuroSP.2017.11"},{"key":"595_CR5","unstructured":"Andriesse D, Chen X, Van Der\u00a0Veen V, Slowinska A, Bos H (2016) An in-depth analysis of disassembly on $$\\{$$Full-Scale$$\\}$$ x86\/x64 binaries. In: 25th USENIX Security Symposium (USENIX Security 16), 583\u2013600"},{"key":"595_CR6","unstructured":"Bai S, Kolter JZ, Koltun V (2018) An empirical evaluation of generic convolutional and recurrent networks for sequence modeling. arXiv:1803.01271"},{"key":"595_CR7","unstructured":"Bao T, Burket J, Woo M, Turner R, Brumley D (2014) Byteweight: Learning to recognize functions in binary code. In: 23rd USENIX Security Symposium (USENIX Security 14), 845\u2013860"},{"key":"595_CR8","doi-asserted-by":"crossref","unstructured":"Cao L, Deng H, Yang Y, Wang C, Chen L (2024) Graph-skeleton: 1% nodes are sufficient to represent billion-scale graph. In: Proceedings of the ACM Web Conference 2024, 570\u2013581","DOI":"10.1145\/3589334.3645452"},{"key":"595_CR9","first-page":"9912","volume":"33","author":"M Caron","year":"2020","unstructured":"Caron M, Misra I, Mairal J, Goyal P, Bojanowski P, Joulin A (2020) Unsupervised learning of visual features by contrasting cluster assignments. Adv Neural Inf Process Syst 33:9912\u20139924","journal-title":"Adv Neural Inf Process Syst"},{"key":"595_CR10","doi-asserted-by":"crossref","unstructured":"Chamith B, Svensson BJ, Dalessandro L, Newton RR (2017) Instruction punning: Lightweight instrumentation for x86-64. In: Proceedings of the 38th ACM SIGPLAN Conference on Programming Language Design and Implementation, 320\u2013332","DOI":"10.1145\/3062341.3062344"},{"key":"595_CR11","unstructured":"Chapman A. Seccomp and Seccomp-BPF. https:\/\/ajxchapman.github.io\/linux\/2016\/08\/31\/seccomp-and-seccomp-bpf.html"},{"key":"595_CR12","first-page":"146","volume":"5","author":"S Chen","year":"2005","unstructured":"Chen S, Xu J, Sezer EC, Gauriar P, Iyer RK (2005) Non-control-data attacks are realistic threats. USENIX Security Symposium 5:146","journal-title":"USENIX Security Symposium"},{"key":"595_CR13","unstructured":"Chen T, Kornblith S, Norouzi M, Hinton G (2020) A simple framework for contrastive learning of visual representations. In: International Conference on Machine Learning, 1597\u20131607 . PmLR"},{"key":"595_CR14","doi-asserted-by":"crossref","unstructured":"Chen X, He K (2021) Exploring simple siamese representation learning. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 15750\u201315758","DOI":"10.1109\/CVPR46437.2021.01549"},{"issue":"4","key":"595_CR15","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3462699","volume":"24","author":"L Cheng","year":"2021","unstructured":"Cheng L, Ahmed S, Liljestrand H, Nyman T, Cai H, Jaeger T, Asokan N, Yao D (2021) Exploitation techniques for data-oriented attacks with existing and potential defense approaches. ACM Transactions on Privacy and Security (TOPS) 24(4):1\u201336","journal-title":"ACM Transactions on Privacy and Security (TOPS)"},{"key":"595_CR16","unstructured":"Contributors C. Capstone Disassembler Website. https:\/\/www.capstone-engine.org\/"},{"key":"595_CR17","unstructured":"Contributors R. Radare2 Website. https:\/\/rada.re\/n\/radare2.html"},{"key":"595_CR18","unstructured":"DeMarinis N, Williams-King K, Jin D, Fonseca R, Kemerlis VP (2020) Sysfilter: Automated system call filtering for commodity software. In: 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020), 459\u2013474"},{"key":"595_CR19","doi-asserted-by":"crossref","unstructured":"Dinesh S, Burow N, Xu D, Payer M (2020) Retrowrite: Statically instrumenting cots binaries for fuzzing and sanitization. In: 2020 IEEE Symposium on Security and Privacy (SP), 1497\u20131511. IEEE","DOI":"10.1109\/SP40000.2020.00009"},{"key":"595_CR20","doi-asserted-by":"crossref","unstructured":"Duck GJ, Gao X, Roychoudhury A (2020) Binary rewriting without control flow recovery. In: Proceedings of the 41st ACM SIGPLAN Conference on Programming Language Design and Implementation, 151\u2013163","DOI":"10.1145\/3385412.3385972"},{"issue":"4","key":"595_CR22","doi-asserted-by":"publisher","first-page":"585","DOI":"10.1145\/3093336.3037716","volume":"52","author":"X Ge","year":"2017","unstructured":"Ge X, Cui W, Jaeger T (2017) Griffin: Guarding control flows using intel processor trace. ACM SIGPLAN Notices 52(4):585\u2013598","journal-title":"ACM SIGPLAN Notices"},{"key":"595_CR23","unstructured":"Ghavamnia S, Palit T, Benameur A, Polychronakis M (2020a) Confine: Automated system call policy generation for container attack surface reduction. In: 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020), pp. 443\u2013458"},{"key":"595_CR24","unstructured":"Ghavamnia S, Palit T, Mishra S, Polychronakis M (2020b) Temporal system call specialization for attack surface reduction. In: 29th USENIX Security Symposium (USENIX Security 20), pp. 1749\u20131766"},{"key":"595_CR25","unstructured":"Glozer, W.: A HTTP Benchmarking Tool. https:\/\/github.com\/wg\/wrk"},{"key":"595_CR26","unstructured":"GNU: Coreutils - GNU Core Utilities. https:\/\/www.gnu.org\/software\/coreutils\/"},{"key":"595_CR27","first-page":"21271","volume":"33","author":"J-B Grill","year":"2020","unstructured":"Grill J-B, Strub F, Altch\u00e9 F, Tallec C, Richemond P, Buchatskaya E, Doersch C, Avila Pires B, Guo Z, Gheshlaghi Azar M et al (2020) Bootstrap your own latent-a new approach to self-supervised learning. Adv Neural Inf Process Syst 33:21271\u201321284","journal-title":"Adv Neural Inf Process Syst"},{"key":"595_CR28","doi-asserted-by":"crossref","unstructured":"Grossklags J, Eckert C, Lin Z (2018) $$\\tau$$cfi: Type-assisted control flow integrity for x86-64 binaries. In: Research in Attacks, Intrusions, and Defenses: 21st International Symposium, RAID 2018, Heraklion, Crete, Greece, September 10-12, 2018, Proceedings, vol. 11050, p. 423. Springer","DOI":"10.1007\/978-3-030-00470-5_20"},{"key":"595_CR29","doi-asserted-by":"crossref","unstructured":"Grover A, Leskovec J (2016) node2vec: Scalable feature learning for networks. In: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 855\u2013864","DOI":"10.1145\/2939672.2939754"},{"key":"595_CR30","doi-asserted-by":"crossref","unstructured":"Han X, Cui S, Qin J, Liu S, Jiang B, Dong C, Lu Z, Liu B (2024) Contramtd: An unsupervised malicious network traffic detection method based on contrastive learning. In: Proceedings of the ACM Web Conference 2024, pp. 1680\u20131689","DOI":"10.1145\/3589334.3645479"},{"key":"595_CR31","doi-asserted-by":"crossref","unstructured":"He K, Fan H, Wu Y, Xie S, Girshick R (2020) Momentum contrast for unsupervised visual representation learning. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 9729\u20139738","DOI":"10.1109\/CVPR42600.2020.00975"},{"key":"595_CR32","doi-asserted-by":"crossref","unstructured":"Hu H, Qian C, Yagemann C, Chung SPH, Harris WR, Kim T, Lee W (2018) Enforcing unique code target property for control-flow integrity. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, pp. 1470\u20131486","DOI":"10.1145\/3243734.3243797"},{"key":"595_CR33","doi-asserted-by":"crossref","unstructured":"Ismail M, Yom J, Jelesnianski C, Jang Y, Min C (2021) Vip: Safeguard value invariant property for thwarting critical memory corruption attacks. In: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, pp. 1612\u20131626","DOI":"10.1145\/3460120.3485376"},{"key":"595_CR34","doi-asserted-by":"crossref","unstructured":"Jelesnianski C, Ismail M, Jang Y, Williams D, Min C (2023) Protect the system call, protect (most of) the world with bastion. In: Proceedings of the 28th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 3, pp. 528\u2013541","DOI":"10.1145\/3582016.3582066"},{"key":"595_CR36","unstructured":"Jin D, Gaidis AJ, Kemerlis VP (2024) Beebox: Hardening $$\\{$$BPF$$\\}$$ against transient execution attacks. In: 33rd USENIX Security Symposium (USENIX Security 24), pp. 613\u2013630"},{"key":"595_CR37","unstructured":"Johannesmeyer B, Slowinska A, Bos H, Giuffrida C (2024) Practical data-only attack generation. In: 33rd USENIX Security Symposium (USENIX Security 24), pp. 1401\u20131418"},{"issue":"9","key":"595_CR38","doi-asserted-by":"publisher","first-page":"12218","DOI":"10.1007\/s11227-024-05895-3","volume":"80","author":"N Joraviya","year":"2024","unstructured":"Joraviya N, Gohil BN, Rao UP (2024) Dl-hids: deep learning-based host intrusion detection system using system calls-to-image for containerized cloud environment. J Supercomput 80(9):12218\u201312246","journal-title":"J Supercomput"},{"key":"595_CR39","doi-asserted-by":"crossref","unstructured":"Kermabon-Bobinnec H, Jarraya Y, Wang L, Majumdar S, Pourzandi M (2024) Phoenix: Surviving unpatched vulnerabilities via accurate and efficient filtering of syscall sequences. In: Proceedings of the 2024 Network and Distributed System Security Symposium . Internet Society San Diego, CA, USA","DOI":"10.14722\/ndss.2024.24582"},{"key":"595_CR40","unstructured":"Khandaker MR, Liu W, Naser A, Wang Z, Yang J (2019) Origin-sensitive control flow integrity. In: 28th USENIX Security Symposium (USENIX Security 19), pp. 195\u2013211"},{"key":"595_CR41","unstructured":"Labs, O.S.D.: DBT-2. https:\/\/github.com\/osdldbt\/dbt2"},{"issue":"1","key":"595_CR42","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1145\/357062.357071","volume":"1","author":"T Lengauer","year":"1979","unstructured":"Lengauer T, Tarjan RE (1979) A fast algorithm for finding dominators in a flowgraph. ACM Transactions on Programming Languages and Systems (TOPLAS) 1(1):121\u2013141","journal-title":"ACM Transactions on Programming Languages and Systems (TOPLAS)"},{"key":"595_CR43","unstructured":"Liu D, Ji S, Lu K, He Q (2024) Improvingindirect-call analysis in llvm with type and data-flow co-analysis. In: 33rd USENIX Security Symposium (USENIX Security 24), pp. 5895\u20135912"},{"issue":"5","key":"595_CR44","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3214304","volume":"51","author":"M Liu","year":"2018","unstructured":"Liu M, Xue Z, Xu X, Zhong C, Chen J (2018) Host-based intrusion detection system with system calls: Review and future trends. ACM computing surveys (CSUR) 51(5):1\u201336","journal-title":"ACM computing surveys (CSUR)"},{"issue":"6","key":"595_CR45","doi-asserted-by":"publisher","first-page":"190","DOI":"10.1145\/1064978.1065034","volume":"40","author":"C-K Luk","year":"2005","unstructured":"Luk C-K, Cohn R, Muth R, Patil H, Klauser A, Lowney G, Wallace S, Reddi VJ, Hazelwood K (2005) Pin: building customized program analysis tools with dynamic instrumentation. Acm sigplan notices 40(6):190\u2013200","journal-title":"Acm sigplan notices"},{"issue":"3","key":"595_CR46","doi-asserted-by":"publisher","first-page":"371","DOI":"10.1109\/TSE.2010.60","volume":"37","author":"PK Manadhata","year":"2010","unstructured":"Manadhata PK, Wing JM (2010) An attack surface metric. IEEE Trans Software Eng 37(3):371\u2013386","journal-title":"IEEE Trans Software Eng"},{"key":"595_CR47","unstructured":"Manual, L.P.: Bpf: Perform a Command on an Extended BPF Map or Program. https:\/\/man7.org\/linux\/man-pages\/man2\/bpf.2.html"},{"key":"595_CR48","unstructured":"Mirsky Y, Macon G, Brown M, Yagemann C, Pruett M, Downing E, Mertoguno S, Lee W (2023) Vulchecker: Graph-based vulnerability localization in source code. In: 32nd USENIX Security Symposium (USENIX Security 23), pp. 6557\u20136574"},{"key":"595_CR49","unstructured":"Moore S, Dimoulas C, King D, Chong S (2014) Shill: A secure shell scripting language. In: 11th USENIX Symposium on Operating Systems Design and Implementation (OSDI 14), pp. 183\u2013199"},{"issue":"3","key":"595_CR51","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1145\/226295.226317","volume":"21","author":"AJ Offutt","year":"1996","unstructured":"Offutt AJ, Hayes JH (1996) A semantic model of program faults. ACM SIGSOFT Software Engineering Notes 21(3):195\u2013200","journal-title":"ACM SIGSOFT Software Engineering Notes"},{"key":"595_CR52","unstructured":"Qian C, Hu H, Alharthi M, Chung PH, Kim T, Lee W (2019) Razor: A framework for post-deployment software debloating. In: 28th USENIX Security Symposium (USENIX Security 19), pp. 1733\u20131750"},{"key":"595_CR53","doi-asserted-by":"crossref","unstructured":"Rajagopalan VL, Kleftogiorgos K, G\u00f6ktas E, Xu J, Portokalidis G (2023) Syspart: Automated temporal system call filtering for binaries. In: Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, pp. 1979\u20131993","DOI":"10.1145\/3576915.3623207"},{"issue":"5","key":"595_CR54","doi-asserted-by":"publisher","first-page":"1467","DOI":"10.1145\/186025.186041","volume":"16","author":"G Ramalingam","year":"1994","unstructured":"Ramalingam G (1994) The undecidability of aliasing. ACM Transactions on Programming Languages and Systems (TOPLAS) 16(5):1467\u20131471","journal-title":"ACM Transactions on Programming Languages and Systems (TOPLAS)"},{"key":"595_CR55","unstructured":"Schrammel D, Weiser S, Sadek R, Mangard S (2022) Jenny: Securing syscalls for pku-based memory isolation systems. In: 31st USENIX Security Symposium (USENIX Security 22), pp. 936\u2013952"},{"key":"595_CR56","doi-asserted-by":"crossref","unstructured":"Snyder P, Taylor C, Kanich C (2017) Most websites don\u2019t need to vibrate: A cost-benefit approach to improving browser security. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 179\u2013194","DOI":"10.1145\/3133956.3133966"},{"key":"595_CR57","unstructured":"SQLite: Temporary Files Used By SQLite. https:\/\/www.sqlite.org\/tempfiles.html"},{"key":"595_CR58","doi-asserted-by":"crossref","unstructured":"Th\u00e9venon G, Nguetchouang K, Lazri K, Tchana A, Olivier P (2024) B-side: Binary-level static system call identification. In: Proceedings of the 25th International Middleware Conference, pp. 225\u2013237","DOI":"10.1145\/3652892.3700761"},{"key":"595_CR59","doi-asserted-by":"crossref","unstructured":"Wang H, Gao Z, Zhang C, Sha Z, Sun M, Zhou Y, Zhu W, Sun W, Qiu H, Xiao X (2024) Clap: Learning transferable binary code representations with natural language supervision. In: Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis, pp. 503\u2013515","DOI":"10.1145\/3650212.3652145"},{"key":"595_CR60","doi-asserted-by":"crossref","unstructured":"Wartell R, Zhou Y, Hamlen KW, Kantarcioglu M, Thuraisingham B (2011) Differentiating code from data in x86 binaries. In: Joint European Conference on Machine Learning and Knowledge Discovery in Databases, pp. 522\u2013536 . Springer","DOI":"10.1007\/978-3-642-23808-6_34"},{"key":"595_CR61","doi-asserted-by":"crossref","unstructured":"Williams-King D, Kobayashi H, Williams-King K, Patterson G, Spano F, Wu YJ, Yang J, Kemerlis VP (2020) Egalito: Layout-agnostic binary recompilation. In: Proceedings of the Twenty-Fifth International Conference on Architectural Support for Programming Languages and Operating Systems, pp. 133\u2013147","DOI":"10.1145\/3373376.3378470"},{"key":"595_CR62","unstructured":"Xia T, Hu H, Wu D (2024) Deeptype: Refining indirect call targets with strong multi-layer type analysis. In: 33rd USENIX Security Symposium (USENIX Security 24), pp. 5877\u20135894"},{"key":"595_CR63","unstructured":"Yasukata K, Tazaki H, Aublin P-L, Ishiguro K (2023) zpoline: a system call hook mechanism based on binary rewriting. In: 2023 USENIX Annual Technical Conference (USENIX ATC 23), pp. 293\u2013300"},{"key":"595_CR64","unstructured":"Ye H, Liu S, Zhang Z, Hu H (2023) Viper: Spotting syscall-guard variables for data-only attacks. In: 32nd USENIX Security Symposium (USENIX Security 23), pp. 1397\u20131414"},{"key":"595_CR65","unstructured":"Zbontar J, Jing L, Misra I, LeCun Y, Deny S (2021) Barlow twins: Self-supervised learning via redundancy reduction. In: International Conference on Machine Learning, pp. 12310\u201312320 . PMLR"},{"issue":"2","key":"595_CR66","doi-asserted-by":"publisher","first-page":"1431","DOI":"10.1109\/TSC.2022.3173791","volume":"16","author":"D Zhan","year":"2022","unstructured":"Zhan D, Yu Z, Yu X, Zhang H, Ye L (2022) Shrinking the kernel attack surface through static and dynamic syscall limitation. IEEE Trans Serv Comput 16(2):1431\u20131443","journal-title":"IEEE Trans Serv Comput"},{"key":"595_CR67","doi-asserted-by":"crossref","unstructured":"Zhu W, Feng Z, Zhang Z, Chen J, Ou Z, Yang M, Zhang C (2023) Callee: Recovering call graphs for binaries with transfer and contrastive learning. In: 2023 IEEE Symposium on Security and Privacy (SP), pp. 2357\u20132374 . IEEE","DOI":"10.1109\/SP46215.2023.10179482"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-026-00595-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-026-00595-2","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-026-00595-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T09:20:28Z","timestamp":1779960028000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-026-00595-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,28]]},"references-count":64,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["595"],"URL":"https:\/\/doi.org\/10.1186\/s42400-026-00595-2","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,28]]},"assertion":[{"value":"16 September 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 April 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 May 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"174"}}